Impact
A use‑after‑free bug exists in the WebAudio implementation within Google Chrome that permits a remote attacker to run arbitrary code inside the browser’s sandbox from a specially crafted web page. The flaw allows an attacker to trigger memory corruption after a freed object has been incorrectly accessed, leading to execution of attacker‑supplied code. The impact is high, threatening confidentiality, integrity, and availability of the user’s system if the browser is exploited. The weakness is identified as CWE-416 and CWE-825.
Affected Systems
Google Chrome versions prior to 148.0.7778.216 are affected. The issue applies to desktop releases of the stable channel and any builds that have not yet incorporated the fix from the Chrome update series released in May 2026.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. Exploitation requires the victim to load a malicious page that contains the crafted payload, making the attack vector web‑based. No EPSS score is currently available, and the flaw is not listed in CISA’s KEV catalog, but the potential for arbitrary code execution makes it a critical risk. Prompt patching is essential to mitigate this threat.
OpenCVE Enrichment